Avoid and report phishing emails (2024)

Learn how to spot deceptive requests online and take recommended steps to help protect your Gmail and Google Account.

What phishing is

Phishing is an attempt to steal personal information or break in to online accounts using deceptive emails, messages, ads, or sites that look similar to sites you already use. For example, a phishing email might look like it's from your bank and request private information about your bank account.

Phishing messages or content may:

  • Ask for your personal or financial information.
  • Ask you to click links or download software.
  • Impersonate a reputable organization, like your bank, a social media site you use, or your workplace.
  • Impersonate someone you know, like a family member, friend, or coworker.
  • Look exactly like a message from an organization or person you trust.

Avoid phishing messages & content

To help you avoid deceptive messages and requests, follow these tips.

1.Pay attention to warnings from Google

Google uses advanced security to warn you about dangerous messages, unsafe content, or deceptive websites. If you receive a warning, avoid clicking links, downloading attachments, or entering personal information. Even if you don’t receive a warning, don’t click links, download files, or enter personal info in emails, messages, webpages, or pop-ups from untrustworthy or unknown providers.

2.Never respond to requests for private info

Don’t respond to requests for your private infoover email, text message, or phone call.

Always protect your personal and financial info, including your:

  • Usernames and passwords, including password changes
  • Social Security or government identification numbers
  • Bank account numbers
  • PINs (Personal Identification Numbers)
  • Credit card numbers
  • Birthday
  • Other private information, like your mother’s maiden name

Tip: Only give out contact info like your email address or phone number to a website if you’ve confirmed it’s reputable. Don’t post your contact info on public forums.

3.Don’t enter your password after clicking a link in a message

If you’re signed in to an account, emails from Google won’t ask you to enter the password for that account.

If you click a link and are asked to enter the password for your Gmail, your Google Account, or another service, don’t enter your information, go directly to the website you want to use.

If you think a security email that looks like it’s from Google might be fake, go directly to

myaccount.google.com/notifications

. On that page, you can check your Google Account’s recent security activity.

4.Beware of messages that sound urgent or too good to be true

Scammers use emotion to try to get you to act without thinking.

Beware of urgent-sounding messages

For example, beware of urgent-sounding messages that appear to come from:

  • People you trust, like a friend, family member, or person from work. Scammers often use social media and publicly available information to make their messages more realistic and convincing. To find out if the message is authentic, contact your friend, family member, or colleague directly. Use the contact info you normally use to communicate with them.
  • Authority figures, like tax collectors, banks, law enforcement, or health officials. Scammers often pose as authority figures to request payment or sensitive personal information. To find out if the message is authentic, contact the relevant authority directly.

Tip: Beware of scams related to COVID-19, which are increasingly common. Learn more about tips toavoid COVID-19 scams.

Beware of messages that seem too good to be true

Beware of messages or requests that seem too good to be true. For example, don’t be scammed by:

  • Get rich quick scams. Never send money or personal information to strangers.
  • Romance scams. Never send money or personal info to someone you met online.
  • Prize winner scams. Never send money or personal info to someone who claims you won a prize or sweepstakes.

5.Stop & think before you click

Scammers often try to deliver unwanted software in links through email, social media posts or messages, and text messages. Never clicks links from strangers or untrustworthy sources.

Use tools to help protect against phishing

1.Use Gmail to help you identify phishing emails

Gmail is designed to help protect your account by automatically identifying phishing emails. Look out for warnings about potentially harmful emails and attachments.

Note: Gmail won’t ever ask you for personal information, like your password, over email.

When you get an email that looks suspicious, here are a few things to check for:

  • Check that the email address and the sender name match.
  • Check if the email is authenticated.
  • See if the email address and the sender name match.
  • On a computer, you can hover over any links before you click on them. If the URL of the link doesn't match the description of the link, it might be leading you to a phishing site.
  • Check the message headers to make sure the "from" header isn't showing an incorrect name.

2. Use Safe Browsing in Chrome

To get alerts about malware, risky extensions, phishing or sites on Google’s list of potentially unsafe sites, use Safe Browsing in Chrome.

In your Safe Browsing settings, choose Enhanced Protection for additional protections and to help improve Safe Browsing and overall web security.

You can download Chrome at no charge.

3. Check for unsafe saved passwords

You can

find and change any unsafe passwords saved in your Google Account

to help secure your accounts.

4. Help protect your Google Account password

To get notified if you enter your Google Account password on a non-Google site, turn on Password Alert for Chrome. That way, you’ll know if a site is impersonating Google, and you can change your password if it gets stolen.

5. Learn about 2-Step Verification

With 2-Step Verification, you add an extra layer of security to your account in case your password is stolen. Learn how you can

protect your account with 2-Step Verification

.

Report phishing emails

When we identify that an email may be phishing or suspicious, we might show a warning or move the email to Spam. If an email wasn't marked correctly, follow the steps below to mark or unmark it as phishing.

Important:When you manually move an email into your Spam folder, Google receives a copy of the email and any attachments. Google may analyze these emails and attachments to help protect our users from spam and abuse.

Report an email as phishing

  1. On a computer, go toGmail.
  2. Open the message.
  3. Next to Reply Avoid and report phishing emails (1), click More Avoid and report phishing emails (2).
  4. Click Report phishing.

Report an email incorrectly marked as phishing

  1. On a computer, go toGmail.
  2. Open the message.
  3. Next to Reply Avoid and report phishing emails (3), click More Avoid and report phishing emails (4).
  4. Click Report not phishing.

Need more help?

Try these next steps:

Post to the help community Get answers from community members
Avoid and report phishing emails (2024)

FAQs

What is the best way to report phishing emails? ›

Forward phishing emails to [email protected] (an address used by the Anti-Phishing Working Group, which includes ISPs, security vendors, financial institutions, and law enforcement agencies). Let the company or person that was impersonated know about the phishing scheme.

Is it worth reporting phishing emails? ›

By reporting phishing attempts, you can: reduce the amount of scam communications you receive. make yourself a harder target for scammers. protect others from cyber crime online.

Is it better to delete or report phishing emails? ›

Delete phishing emails immediately. We encourage you to report phishing phone calls and emails: [email protected].

How do I stop unwanted phishing emails? ›

How to get rid of spam emails
  1. Mark as spam. ...
  2. Delete spam emails. ...
  3. Keep your email address private. ...
  4. Use a third-party spam filter. ...
  5. Change your email address. ...
  6. Unsubscribe from email lists.

Is it better to block sender or report phishing emails? ›

While filtering addresses some spam emails, you should outright block spam email addresses that are persistent, dangerous, or fake. And remember to report any internet scams you come across, such as Apple ID phishing scams and other threats.

What is the best defense against phishing emails? ›

Never click any links or attachments in suspicious emails or Teams messages. If you receive a suspicious message from an organization and worry the message could be legitimate, go to your web browser and open a new tab. Then go to the organization's website from your own saved favorite, or via a web search.

What happens when you report emails as phishing? ›

Your report of a phishing email will help us to act quickly, protecting many more people from being affected. The National Cyber Security Centre (NCSC) will analyse the suspect email and any websites it links to. They'll use any additional information you've provided to look for and monitor suspicious activity.

Does opening a phishing email do anything? ›

Just opening the phishing message without taking any further action will not compromise your data. However, hackers can still gather some data about you, even if all you did was open the email.

Does reporting phishing emails do anything on Gmail? ›

When we identify that an email may be phishing or suspicious, we might show a warning or move the email to Spam. If an email wasn't marked correctly, follow the steps below to mark or unmark it as phishing.

Can spammers tell if you delete an email? ›

When your mail client attempts to open that file to render it for you, the spammer knows you opened their message. The spammer will not know whether you deleted their message, but if it embeds a pixel, then they may find out that you opened the message.

What is the strongest indicator of a phishing email? ›

Look for these common scam warning signs before you react or respond to a suspicious email:
  1. It's sent from a public or free email domain. ...
  2. The “From” name and email domain don't match. ...
  3. The sender has spoofed a company's domain name. ...
  4. You get a warning from your email provider. ...
  5. You're told there's an issue with your account.
Mar 21, 2024

Should you delete phishing emails immediately? ›

If you receive any unwanted email, the best approach in almost every case is to delete it immediately. It is often clear from the Subject line that a message is junk, so you may not even need to open the message to read it. Some such messages invite you to reply if you want to be removed from their list.

How do I permanently delete phishing emails? ›

  1. Hold down the Shift key on your keyboard and click Delete in the top control bar.
  2. In the confirmation window that appears, click Yes. ...
  3. Select the Folder tab in the top menu.
  4. Click Ok.
  5. A warning will appear that you are about to permanently delete the selected messages and you will no longer be able to recover them.

Why am I getting so many phishing emails? ›

Your email address has been shared publicly, leaked, or sold: When you sign up for a service or make a purchase online, you are often required to provide an email address. This email address may be collected and sold to third-party marketers who use it to send out spam emails.

Will phishing emails eventually stop? ›

Will spam emails eventually stop? Spam emails will likely always be an issue we all deal with. However, if you block spam senders and take other recommended steps to secure your inbox, you can cut down the amount of spam emails you receive.

What should you do with an email you suspect of phishing? ›

Online Messages
  1. Do not open it. ...
  2. Delete it immediately to prevent yourself from accidentally opening the message in the future.
  3. Do not download any attachments accompanying the message. ...
  4. Never click links that appear in the message. ...
  5. Do not reply to the sender. ...
  6. Report it.

Which button is used to report phishing? ›

For Outlook over the web users (Windows and OS X), the Report Phishing button is called “Phish Alert” button will appear under the (ellipse) icon to the right of the message (see below).

Which of the following is the proper way to handle phishing emails? ›

Never provide personal financial information, including your Social Security number, account numbers or passwords, over the phone or the Internet if you did not initiate the contact. Never click on the link provided in an email you believe is fraudulent. It may contain a virus that can contaminate your computer.

Does it help to report phishing in Outlook? ›

A new feature in Outlook lets you flag emails as either Phishing or Junk. By using this Report tool, the message will be reported to Microsoft to assist them in improving their filters. Please note that this reporting feature is only available in newer versions of Outlook.

Top Articles
XTB Erfahrungen 2024: Aktueller Broker Test & alle Kosten
Flea Market Flipping: Make Money Flipping Stuff from Thrift Stores
123Movies Encanto
Palm Coast Permits Online
Libiyi Sawsharpener
Ffxiv Palm Chippings
Euro (EUR), aktuální kurzy měn
Boomerang Media Group: Quality Media Solutions
Coffman Memorial Union | U of M Bookstores
Es.cvs.com/Otchs/Devoted
Practical Magic 123Movies
What Auto Parts Stores Are Open
Stl Craiglist
Arrests reported by Yuba County Sheriff
Teamexpress Login
Fnv Turbo
Best Cav Commanders Rok
Hardly Antonyms
Bros Movie Wiki
Palace Pizza Joplin
Studentvue Columbia Heights
Lancasterfire Live Incidents
Invert Clipping Mask Illustrator
Labby Memorial Funeral Homes Leesville Obituaries
Zoe Mintz Adam Duritz
Www Craigslist Com Bakersfield
Hewn New Bedford
Babbychula
Watertown Ford Quick Lane
Culver's.comsummerofsmiles
Truvy Back Office Login
Narragansett Bay Cruising - A Complete Guide: Explore Newport, Providence & More
Farm Equipment Innovations
Paradise Point Animal Hospital With Veterinarians On-The-Go
Page 2383 – Christianity Today
Deepwoken: Best Attunement Tier List - Item Level Gaming
Robert A McDougal: XPP Tutorial
Kacey King Ranch
Fairwinds Shred Fest 2023
NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
Sedano's Supermarkets Expands to Orlando - Sedano's Supermarkets
Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
Snohomish Hairmasters
Thanksgiving Point Luminaria Promo Code
Daly City Building Division
Noaa Marine Weather Forecast By Zone
No Boundaries Pants For Men
Top 40 Minecraft mods to enhance your gaming experience
Rise Meadville Reviews
Epower Raley's
ats: MODIFIED PETERBILT 389 [1.31.X] v update auf 1.48 Trucks Mod für American Truck Simulator
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 5704

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.